The Allure of Go's Cross-Platform Capability: A Gateway for Threat Actors to Mac and Linux

Anmol Maurya

BSides NYC 2025 (0x05) · Day 1 · Tech - Other

In an insightful presentation at BSides NYC, Anmol Maurya, a malware and threat researcher at Paletto Networks (formerly with CrowdStrike), unveiled the growing trend of threat actors leveraging Golang's inherent cross-platform capabilities to target macOS and Linux systems. While the security industry's telemetry often heavily favors Windows-centric threats, Maurya's talk highlighted a significant and increasing shift towards Go-based malware impacting alternative operating systems. This discussion is critical for defenders, as Golang's unique features, such as static linking and straightforward cross-compilation, provide adversaries with a potent tool for developing highly portable and often stealthy malicious payloads.

AI review

A competent, well-structured survey of Go malware targeting macOS and Linux that covers the right ground — static linking, cross-compilation, binary analysis methodology, platform-specific detection — without breaking new ground for anyone already living in this space. Good BSides-tier content; not a Black Hat research drop.

Watch on YouTube